kaxil commented on PR #73374: URL: https://github.com/apache/airflow/pull/73374#issuecomment-5881036472
Round 3 at add8c41. Everything from round 2 is addressed: host-first account resolution with a `None` return for the empty case, the partial service-principal raise, the sovereign-cloud raise, the env-precedence guard, legacy `extra__wasb__` extras, the parametrized resolver tests, and the docs paragraphs. Keeping `abfs://` for a separate PR is fine. One new item, which is a gap in the env-precedence guard rather than a new bug: object_store also reads `AZURE_CLIENT_ID`/`AZURE_CLIENT_SECRET`/`AZURE_TENANT_ID` and `AZURE_STORAGE_MASTER_KEY` from the environment and ranks both above a connection SAS token, so a worker with either set still silently ignores the connection's credential. `AZURE_STORAGE_SAS_KEY`, which is in the list, never outranks an explicit credential. Details and a probe against datafusion 51.0.0 are in the inline comment. Two non-blocking notes: the sovereign-cloud error text points at a variable the raise does not consult, and SAS is chosen ahead of `shared_access_key` where `WasbHook` does the reverse, which matters for a connection holding a live key and an expired SAS. Verdict: hold for the guard list, then this looks ready. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
